I would like to block a specific IP address (10.200.200.109) on my Lan from inbound and outbound traffic to the internet. All my Lan computers still need to be able to access that computer and vice versa since it's my NAS. Here is my current pf.conf:

You have a blend of rules with the "quick" option, and rules without it. Because of this complication, I recommend adding new "quick" rules relatively early in your rule set, perhaps before any other quick rules, as your redirects are less specific than this example below.

Keep in mind that you can get tangled up with "in" "out" and "on" when trying to match traffic, or ... trying NOT to match traffic. And as well, the blend of quick and standard rules can sometimes be difficult to manage.

Code:

block quick on $wan from any to 10.200.200.109
block quick on $wan from 10.200.200.109 to any